Am I responsible for securing the data of my customers at my Azal Coffee franchise?
Azal_Coffee Franchise · 2024 FDDAnswer from 2024 FDD Document
You are responsible for securing the data of your customers. You must comply with industry standards and all applicable laws relating to the protection of customer information and other personal information. You must comply with the PCI Requirements in connection with your Store. It is recommended that you also comply with the ISO/IEC 27000-series information security standards (or other comparable third-party information security standards) ("Information Security Standards") in connection with the Store. It is your responsibility to research and understand the PCI Requirements and Information Security Standards, other industry standards, and applicable laws and to ensure that your business policies and practices comply with these requirements. You must periodically participate in audits of your information technology systems and data security policies by third party auditors as specified by us. We have the right to engage a vendor to consult with and advise you on compliance with the PCI Requirements and Information Security Standards and to require you to pay a portion of the cost of the vendor's services as determined under our policies or to directly engage the vendor for these purposes. Also, we will have the right to acquire a cyber insurance policy for our franchise system and to require you to pay a portion of the cost of the cyber insurance policy as determined under our policies and procedures.
Source: Item 11 — FRANCHISOR'S ASSISTANCE, ADVERTISING, COMPUTER SYSTEMS AND TRAINING (FDD pages 27–36)
What This Means (2024 FDD)
According to Azal Coffee's 2024 Franchise Disclosure Document, franchisees are responsible for securing their customers' data. As an Azal Coffee franchisee, you must adhere to industry standards and all relevant laws concerning the protection of customer and personal information. This includes complying with PCI Requirements related to your store.
Azal Coffee also recommends that franchisees comply with ISO/IEC 27000-series information security standards or other comparable third-party information security standards. It is your responsibility to research and understand these requirements, industry standards, and applicable laws to ensure your business policies and practices are compliant.
Furthermore, you must periodically participate in audits of your information technology systems and data security policies conducted by third-party auditors as specified by Azal Coffee. Azal Coffee retains the right to engage a vendor to advise you on compliance with PCI Requirements and Information Security Standards, with the cost potentially being shared between you and the franchisor. Azal Coffee also has the right to acquire a cyber insurance policy for the franchise system, and you may be required to pay a portion of the cost.